Mod Rewrite问题:HTTPS重定向引发404错误
Hey fellow dev, let's break down why adding your HTTPS enforcement rule is breaking your URL rewrites and how to fix it. Based on your .htaccess code, here are the key areas to check and adjust:
1. Fix the Order of Your Rules
Right now, your HTTPS rule is at the bottom of your rewrite stack. That means when someone visits an HTTP URL like http://example.com/projects/, Apache first processes your rewrite rule (converting it to all-projects.php), then triggers the HTTPS redirect. The problem? You're redirecting the rewritten PHP file path (https://example.com/all-projects.php) instead of the friendly URL. If your server expects only friendly URLs (or has a misconfiguration in the HTTPS site), this can lead to 404s.
Quick Fix: Move your HTTPS enforcement block to the very top, right after RewriteEngine ON. This way, Apache first redirects the HTTP friendly URL to HTTPS, then processes your rewrite rules on the HTTPS request:
RewriteEngine ON # Force HTTPS first <If "%{HTTP_HOST} == 'example.com'"> RewriteCond %{HTTPS} !=on RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301,NE] </If> # Rest of your rewrite rules follow here...
2. Verify <If> Directive Compatibility
The <If> directive is only supported in Apache 2.4 and later. If your server runs an older version (like Apache 2.2), this block will be ignored, leading to inconsistent behavior. To make it compatible with older versions, replace the <If> block with a standard RewriteCond:
RewriteCond %{HTTP_HOST} ^example\.com$ [NC] RewriteCond %{HTTPS} !=on RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301,NE]
3. Check for HTTPS Site Configuration Mismatches
Make sure your HTTPS virtual host (in Apache's httpd.conf or ssl.conf) matches your HTTP configuration exactly:
- The
DocumentRootshould point to the same directory as your HTTP site. mod_rewritemust be enabled for the HTTPS site (ensureRewriteEngine ONis set in the HTTPS vhost config or that.htaccessis allowed withAllowOverride All).- If using a CDN or reverse proxy, confirm it passes the correct
HTTPSheader to Apache. Some proxies useX-Forwarded-Protoinstead, so adjust yourRewriteCondto check that:RewriteCond %{HTTP:X-Forwarded-Proto} !https.
4. Clear 301 Redirect Caches
Since you're using R=301 (permanent redirect), browsers and proxies cache this redirect aggressively. If you had a misconfigured rule earlier, the cached redirect might still send users to the wrong URL. Test with R=302 (temporary redirect) first to avoid caching, and clear your browser cache before retesting.
5. Add a RewriteBase Directive
If your site is hosted in a subdirectory (not the server's root), missing RewriteBase can cause path resolution issues after HTTPS redirects. Add this line right after RewriteEngine ON:
RewriteBase /
Adjust the path if your site is in a subfolder (e.g., RewriteBase /my-site/).
6. Debug with Apache's Rewrite Log
Enable Apache's rewrite logging to see exactly how your rules are processed. Add these lines to your Apache config (or .htaccess if allowed) temporarily:
# For Apache 2.4+ LogLevel alert rewrite:trace3
This log will show you each step of the rewrite process, helping you spot where the HTTPS rule is interfering.
内容的提问来源于stack exchange,提问作者Daniel Kilburn

